CVE-2026-44422
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR type or ownership. When the same ref-id is reused across two pointer fields, the parser assigns the same heap object to both output fields. The generic destructor later walks each field independently and destroys/frees both pointers. This causes a malicious-server-triggerable heap use-after-free / double-free in the FreeRDP client's RDPEAR authentication-redirection path. This vulnerability is fixed in 3.26.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13- osv-coords10 versionspkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0pkg:rpm/almalinux/freerdp-develpkg:rpm/almalinux/freerdp-serverpkg:rpm/opensuse/freerdp&distro=openSUSE%20Leap%2016.0pkg:rpm/almalinux/freerdppkg:rpm/opensuse/freerdp&distro=openSUSE%20Tumbleweedpkg:rpm/almalinux/freerdp-libspkg:rpm/almalinux/libwinprpkg:rpm/almalinux/libwinpr-devel
< 3.26.0-160000.1.1+ 9 more
- (no CPE)range: < 3.26.0-160000.1.1
- (no CPE)range: < 3.26.0-160000.1.1
- (no CPE)range: < 2:3.10.3-12.el10_2.6
- (no CPE)range: < 2:3.10.3-12.el10_2.6
- (no CPE)range: < 3.26.0-160000.1.1
- (no CPE)range: < 2:3.10.3-12.el10_2.6
- (no CPE)range: < 3.26.0-3.1
- (no CPE)range: < 2:3.10.3-12.el10_2.6
- (no CPE)range: < 2:3.10.3-12.el10_2.6
- (no CPE)range: < 2:3.10.3-12.el10_2.6
Patches
Vulnerability mechanics
References
6- github.com/FreeRDP/FreeRDP/security/advisories/GHSA-j9q5-7g8m-jc9vnvdExploitMitigationVendor Advisory
- access.redhat.com/errata/RHSA-2026:36203nvd
- access.redhat.com/errata/RHSA-2026:46393nvd
- access.redhat.com/security/cve/CVE-2026-44422nvd
- bugzilla.redhat.com/show_bug.cginvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44422.jsonnvd
News mentions
0No linked articles in our index yet.